{"id":"MGASA-2014-0465","summary":"Updated srtp package fixes security vulnerability","details":"Fernando Russ from Groundworks Technologies reported a buffer overflow flaw\nin srtp, Cisco's reference implementation of the Secure Real-time Transport\nProtocol (SRTP), in how the crypto_policy_set_from_profile_for_rtp() function\napplies cryptographic profiles to an srtp_policy. A remote attacker could\nexploit this vulnerability to crash an application linked against libsrtp,\nresulting in a denial of service (CVE-2013-2139).\n","modified":"2026-04-16T06:24:30.295904216Z","published":"2014-11-21T12:44:16Z","upstream":["CVE-2013-2139"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0465.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14200"},{"type":"WEB","url":"https://www.debian.org/security/2014/dsa-2840"}],"affected":[{"package":{"name":"srtp","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/srtp?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.4-3.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0465.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}